ANSI X9.99-2004 pdf download Privacy Impact Assessment Standard
1 Scope
This standard recognizes that a Privacy Impact Assessment (PIA) is an important management tool that should be used within an organization or by third parties to identify and mitigate privacy issues and risks associated with processing consumer data using automated, networked information systems. This PIA Standard scope:
• provides references to educate the reader on privacy topics and financial privacy in particular
• describes the privacy impact assessment activity, in general
• defines the common components of a PIA regardless of business system affecting financial institutions, and
• explains how to improve the quality of business-system specific PIAs
A privacy impact assessment (PIA) is different than a privacy compliance audit. A compliance audit determines an institution’s current level of compliance with the law and identifies steps to avoid future non- compliance with the law. While there are similarities between PIAs and privacy compliance audits, in that they use some of the same skills and that they are tools used to avoid breaches of privacy, the primary concern of a compliance audit is to just meet the requirements of the law, whereas a PIA should delve much further to identify ways to optimally safeguard privacy. Note: Some laws (e.g. the Gram Leach Bliley act (GLB) address both financial privacy rules and financial security guidelines. X9.99 addresses the privacy aspects, but does not address the security aspects (e.g. the implementation of an information security program (ISP)).
This standard recognizes that the choices of system development and risk management procedures are business decisions and as such, the business decision makers must be informed in order to make educated decisions for their institutions. This standard provides a privacy impact assessment structure (e.g., common PIA components, definitions, and informative annexes) for institutions that handle financial information who are seeking to use a PIA as a tool to plan for and to manage privacy issues within business systems that they consider to be vulnerable.
ANSI X9.99-2004 pdf download
PS:Thank you for your support!